During an IS audit, an auditor discovers that a control is functioning as intended but the risk it mitigates has already been accepted by management.What is the BEST course of action?